<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-westerbaan-dnssec-mldsa-02" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="ML-DSA for DNSSEC">Module-Lattice Digital Signature Algorithm for DNSSEC</title>
    <seriesInfo name="Internet-Draft" value="draft-westerbaan-dnssec-mldsa-02"/>
    <author initials="B. E." surname="Westerbaan" fullname="Bas Westerbaan">
      <organization>Cloudflare</organization>
      <address>
        <email>bas@cloudflare.com</email>
      </address>
    </author>
    <author fullname="Sophie Schmieg">
      <organization>Google</organization>
      <address>
        <email>sschmieg@google.com</email>
      </address>
    </author>
    <date year="2026" month="July" day="22"/>
    <area>Security</area>
    <workgroup>Domain Name System Operations</workgroup>
    <keyword>DNSSEC</keyword>
    <keyword>ML-DSA</keyword>
    <keyword>post-quantum</keyword>
    <keyword>FIPS 204</keyword>
    <keyword>signatures</keyword>
    <abstract>
      <?line 58?>

<t>This document describes how to specify Module-Lattice-Based Digital
Signature Algorithm (ML-DSA) keys and signatures in DNS Security
(DNSSEC).  It uses the ML-DSA-44 parameter set defined in FIPS 204.
ML-DSA-44 is believed to be secure even against adversaries in possession
of a cryptographically relevant quantum computer.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://bwesterb.github.io/draft-westerbaan-dnssec-mldsa/draft-westerbaan-dnssec-mldsa.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-westerbaan-dnssec-mldsa/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Domain Name System Operations Working Group mailing list (<eref target="mailto:dnsop@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/dnsop/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/dnsop/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/bwesterb/draft-westerbaan-dnssec-mldsa"/>.</t>
    </note>
  </front>
  <middle>
    <?line 66?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>DNSSEC, which is broadly defined in <xref target="RFC4033"/>, <xref target="RFC4034"/>, and
<xref target="RFC4035"/>, uses cryptographic keys and digital signatures to provide
authentication of DNS data.  Currently the most popular signature
algorithms in use are RSA and the NIST-specified elliptic curve
signature algorithm ECDSA <xref target="RFC6605"/>.</t>
      <t>All currently specified algorithms rely for their security on the hardness of the
integer factorization problem or the (elliptic curve) discrete
logarithm problem.  A cryptographically relevant quantum computer when built
would be able to solve both of these problems efficiently, and
would therefore be able to forge DNSSEC signatures created with any of
these algorithms.</t>
      <t><xref target="FIPS204"/> specifies the Module-Lattice-Based Digital Signature
Algorithm (ML-DSA), a signature scheme whose security is based on the
hardness of lattice problems over module lattices.  ML-DSA is believed
to be secure even against adversaries in possession of a
cryptographically relevant quantum computer.  <xref target="FIPS204"/> defines three
parameter sets: ML-DSA-44, ML-DSA-65, and ML-DSA-87.</t>
      <t>This document defines the use of DNSSEC's DS, DNSKEY, and RRSIG resource
records (RRs) with the ML-DSA-44 parameter set.  ML-DSA-44 targets NIST
security category 2, which equates to 160 bits of security classical
and post-quantum security. ML-DSA-44 has the smallest keys and signatures
of the three ML-DSA parameter sets, which makes it the most suitable
for use in the DNS.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="dnskey-resource-records">
      <name>DNSKEY Resource Records</name>
      <t>An ML-DSA-44 public key consists of a 1312-octet value as produced by
the key generation algorithm ML-DSA.KeyGen defined in Section 5.1 of
<xref target="FIPS204"/>.  It is encoded into the Public Key field of a DNSKEY
resource record as a simple bit string, using the byte encoding of the
public key described in Section 7.2 of <xref target="FIPS204"/>.</t>
    </section>
    <section anchor="rrsig-resource-records">
      <name>RRSIG Resource Records</name>
      <t>An ML-DSA-44 signature consists of a 2420-octet value as produced by the
signing algorithm ML-DSA.Sign defined in Section 5.2 of <xref target="FIPS204"/>.  It
is encoded into the Signature field of an RRSIG resource record as a
simple bit string, using the byte encoding of the signature described in
Section 7.2 of <xref target="FIPS204"/>.</t>
      <t>Signatures are generated and verified using the "pure" ML-DSA variant
(i.e., not the pre-hash variant HashML-DSA) with an empty context string
(ctx of zero length), as described in Sections 5.2 and 5.3 of
<xref target="FIPS204"/>.  The message signed is the data to be signed as described
in Section 3.1.8.1 of <xref target="RFC4034"/>.</t>
    </section>
    <section anchor="algorithm-number-for-ds-dnskey-and-rrsig-resource-records">
      <name>Algorithm Number for DS, DNSKEY, and RRSIG Resource Records</name>
      <t>The algorithm number associated with the use of ML-DSA-44 in DS, DNSKEY,
and RRSIG resource records is TBD1.  This registration is fully defined
in the IANA Considerations section.</t>
    </section>
    <section anchor="examples">
      <name>Examples</name>
      <t>The following example, in the style of Section 6 of <xref target="RFC6605"/>, shows an
ML-DSA-44 DNSKEY, its corresponding DS record, and an RRSIG over an MX
RRset.  The key was generated deterministically from the 32-octet seed
shown in the PrivateKey field, and the signature was produced using the
deterministic variant of ML-DSA (rnd set to all zeroes) so that the
example is byte-for-byte reproducible.  Because of the size of ML-DSA-44
keys and signatures, the base64-encoded values are wrapped.</t>
      <aside>
        <t><em>Warning</em>: Test vectors provisionally use 18 for the algorithm number. Will
be updated with the number IANA allocates.</t>
      </aside>
      <artwork><![CDATA[
Private-key-format: v1.3
Algorithm: 18 (MLDSA44)
PrivateKey: AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8=

example.com. 3600 IN DNSKEY 257 3 18 (
             17K0clSq4NtF55MNSpjSyX2PE5fReJ2voXAksxbpvslPyZRtQvGbeadBO7qj
             PnFJy0LtURVpOsBB+suYit61/g4dhjEYSZW1ksOX0ilOLhT5CqQUujgmiZrE
             P0zMrLwm6agyuVEY1ctDPL75ZgsAE44IF/YediyidMNq1VTrIqrBFi5KsBrL
             oeOMTv2PgLZbMz0PcuVd/nHOnB67mInnxWEGwP1zgDoq7P6v3teqPLLO2lTR
             K9jNNqeM+XWUO0er0l6ICsRS5XQu0ejRqCr6huWQx1jBWuTShA2SvKGlCQ9A
             SWWX/KfYuVE/GhvabpUKqpjeRnUH1KT1pPBZkhZYLDVy9i7aiQWrNYFnDEoC
             d3oz4Mpylf2PT/bRoKOnaD1l9fX3/GDaAj6CbF+SFEwC99G6EHWYdVPqk2f8
             122ZC3+pnNRa/biDbUPkWfUYffBYR5cJoB6mg1k1+nBGCZDNPcG6QBupS6sd
             3kGsZ6szGdysoGBI1MTu8n7hOpwX0FOPQw8tZC3CQVZg3niHfY2KvHJSOXjA
             QuQoX0MZhGxEEmJCl2hEwQ5Va6IVtacZ5Z0MayqW05hZBx/cws3nUkp77a5U
             6FsxjoVOj+Ky8+36yXGRKCcKr9HlBEw6T9r9n/MfkHhLjo5FlhRKDa9YZRHT
             2ZYrnqla8Ze05fxg8rHtFd46W+9fib3HnZEFHZsoFudPpUUx79wcvnTUSIV/
             R2vNWPIcC2U7O3ak4HamVZowJxhVXMY/dIWaq6uSXwI4YcqM0Pe62yhx9n1V
             Mm10URNa1F9KG6aRGPuyyKMO7JOS7z+XcGbJrdXHEMxkexUU0hfZWMcBfD6Q
             /SDATmdLkEhuk3CjGgAdMvRzl55JBnSefkd/oLdFCPil8jeDErg8Jb04jKCw
             //dHi69CtxZn7arJfEaxKWQ+WG5bBVoMIRlG1PNuZ1vtWGD6BCoxXZgmFk1q
             kjfDWl+/SVSQpb1N8ki5XEqud4S2BWcxZqxCRbW0sIKgnpMj5i8geMW3Z4NE
             be/XNq06NwLUmwiYRJAKYYMzl7xEGbMNepegs4fBkRR0xNQbU+Mql3rLbw6n
             XbZbs55Z5wHnaVfe9vLURVnDGncSK1IE47XCGfFoixTtC8C4AbPm6C3NQ+nA
             6fQXRM2YFb0byIINi7Ej8E+s0bG2hd1aKxuNu/PtkzZw8JWhgLTxktCLELj6
             u9/MKyRRjjLuoKXgyQTKhEeACD87DNLQuLavZ7w1W5SUAl3HsKePqA46Lb/r
             UTKIUdYHgZjpSTZRrnh+wCUfkiujDp9R32Km1yeEzz3SBTkxdt+jJKUSvZSX
             CjbdNKUUqGeR8Os28BRbCatkZRtKAxOymWEaKhxIiRYnWYdooxFAYLpEQ0ht
             9RUioc6IswmFwhb45u0XjdVnswSg1Mr7qIKig0LxepqiauWNtjAIPSw1j99W
             bD9dYqQoVnvJ6ozpXKoPNUdLC/qPM5olCrTfzyCDvo7vvBBV4Y/hU3DuyyYF
             Ztg/8GshGq7EPKKbVMzQD4gVokZe8LRlFcx+QfMSTwnv/3OTCatYspoUWaAL
             zlA46TjJZ49y6w5O5f2q5m2fhXP8l/xCtJWfS/i2HXhDPoawM11ukZHE2L9I
             ezkFwQjP1qwksM633LfPUfhNDtaHuV6uscUzwG8NlwI9kqcIJYN7Wbpst9Tl
             awqHwgOGKujzFbpZJejt76Z5NpoiAnZhUfFqll+fgeznbMBwtVhp5NuXhM8F
             yDCzJCyDEg== )

example.com. 3600 IN DS 59829 18 2 (
             812cb1a22af04380e2f72d91c06c14eb1a918cf30037a8a9c67497e9264b
             4bfa )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 18 2 3600 (
             1440021600 1438207200 59829 example.com.
             kdySHzwB7NftjQSAF7snCeKau3NoqpLNg16h/eHZV8L3Zpi30lkRyiS4FLMM
             ZqTjzbf1A/bShg4qZpYlnfqXN8uqFWF9GEEJOgte1CFdF4GC05gEBU88Kryf
             nGAcpXKafw9htDxZrqmqVSWN+1guW7HyUUFo1IuWTnZKuhZptDJkq+Ml+5ZH
             y4p+2Tdwk8MH7tJlTYk/UVaM1wIXPB2YgJ++kD0zhys5c38rztcaOmMXt6ej
             yAEY37Dc1Z/KsrRQZWv+XZ/CTliuh+dGJHoGuTm5KwS0us884ukWNC/wIU/S
             dlGoBDVXsT163Tr6lTf8pJ4xixcKIN8nsKSFxP9j+AbaN5SofIAvp4LGIFLg
             MKsRV/cqeYo8PegVD2EhAQ2/HVTO3uO8vlqLK7nWVVK2+2aYKIL2EqzjhRYK
             U5DhMwS9ZgbG0niszGXpvZcNcOyABXysdVuaDjnUuamYVACOUrV786LNmt8I
             WDnXWoPPMErPk5vNyHq6+ZHg79UeZpSzx0Ae/1aIfi2WEta9Or5sGItBn6vF
             Wi9kJRuhuoMIXf9CLBV/LHL/PIenBxXSnr2Owg54AuSN2tmk2lDy8BfKzzvx
             TOoKXx4edo96Xv6QWASAxO9JmyEvhnF3SBI6HG3fn2+k8rgJLIHpsr4pZhMh
             4/SQWaojxt51nEIFi1bl7P6sAmCdMP81LSNx05hIkKcPeO33hA2VSDO7GzOE
             snBOzbhUX9gbFr3aNV/Wrbs/cZMAL1I0IKG20jkmEfZ9PeKN0hXCxHJo4hPF
             L2mm9ciGpuXS7oN8f7YublNTwRY8b4plScVICpyBT5UDOgezR9/+DnklL0fz
             IORMTRnpD1hq4BqZMgNMwvczFg3DrSLQP/cBiKLn3toJrkSuU9aXodEqW3lh
             RdMvDUqTtHgMKas5velmabpENAbixiB8n5zoENnMLV6w/13a+yOTT2WUvESg
             HqF92FfQMdQl36noyewmjUFZopirCGV6AkebdVsTY27DtYkGWamLXcm3w2d6
             AYV/LssvyK/Jlnw/E7YRJWkO+8PvHA2tvfQSr8fNC4ll/KHdwr8d0Q8spPcO
             HMMui20XDYeprPmp64hSt4IBuiQusdm3SQsWjQvaUsg8sykZd24S/wNQiGsw
             XaoG6oWYYCZupfvGc0sgb+9qxZU5fSAYKwx5LjYajruvQ5flebAtrUdLuPbG
             Mb2I7Z8c4IvDmbA6ljqMK60w1XI+wU7jSWzoEaiIeAUR1aT925KFMEhmFG3k
             Tr5ZPI57wM7pEI9jBME80lu7D3f4z++icSHSJ5YNa/+kp7eSIT94m4Tj7nel
             mN0WnKFgzGZKnuiDGJew5FFnfB0qfvqUNUPt1rVaIr7rzBBL4j8WQHqOo17A
             +0pnIqKTe1Z8MxFnPwP1eWHa3T/7JeEPSD5JFOpEWxs12twxTC42BrTCckSm
             rfmksfxmJa0mfflaOPHkjahTprrItJzG1efHYCu5nP5rsclZF0hDOR1OZrgK
             2IhnG1VotIPB4+/+70+uD0qcqY3L2yonxFlQS8sEmMcXi9xQTxdFG4NOk/TQ
             G50Oly1tRp9UoLjwTDtlIjh71Lz9lajbAabV4WtIvd7cwaREO0kFAtzIgfJR
             VMasWvUo6e93qQBThzvkCNs8ngsa0jXJL1HrERP+qkiULCDMr19FVimWmIzL
             CkR9pg9WWjruY5krgdVbINUqjsyyGriPEhy2JneNWdOdFoAwkWtGbIpQhHs2
             bLHpG9xPPF+ElqLmjNa76BhXv4caurHYn7K0m4NMVgDywGXoh0OGe/PoXQ4g
             Ht7EbHgbCQO9V8+/1+MWw9ZrU6btOGJ2JVXeyRXYyJarn+cnPL1nWOlq7bMD
             3mazOTNZPc5UENSvDL51hmd3WD71i2u9btqIzjnmSxggPHRsVcOaGXHM3aUJ
             nrDtwi1EY7THlJatS+ItjWQMCDh8g/4LF9S2UWGFc21MimswWvgh1jB/4hYI
             9C8PSCpAeV26dXoANntR/lLms42488dVJ1wyNGjaNNX1itiqFYsNUn3LyT3T
             dVUgBwkfzO1I4UnhDIbsHJWbs7Dl/52Ei4MbpPJXnL1gMNc6SD1EkT1CeY9f
             esHF20wr8tb7V+qPO2TCE26syB9lZ41OSOYgqPYK/OHyoLedQmTOFls0QMj2
             F0bks3pJm/TDDMEuUdhulPatnZBNIXexqNImQUFyipcJ9W5KnD6Wr5+jyULy
             VBQRpWPzipfPFACb5d5lWPtrvh4kurYt3sSdUy+WJKuYb1roxXTZJqP0QDgn
             VEYL5nJnxqSRD9fx7HMRHXODkVioBFmSUgwP5XBljn/YpIgG8Ix42hyKMCti
             yv1gIY3/m8cfHyj5I6xcDHUTZHyM9+KSZeipf6wUnngoZuYzP9N3Nozo8LI+
             w3Mo6s/VjhmsALOYcus720s0MQY5prhkcZYUvgv9YL9R+1Fm7Kxy3cjpnGqy
             WwxN6YmNw/f6C+21Dlex7+09o2ygi0M1NEZZ0FhdaBmxVxtSjbBm3uKu9taW
             0zO534HXlifFkxf6GhboxbGdm1yekVIjDLnC+iodQyLwIi0vvc435Xk4GRBs
             8D5Pxf3vT3tgPy5sDXbJ3lT58MekKdT/HobugDOdu0ltGenFjnKFhdJudvQ/
             FFjqJk1HYnjxxdP3QYKlSHOv2ADtRqgI0VHLJmECOifYr90uWml1uzaUzK0X
             Tulm8fn6lfpF3EWJYSsq1iXQWuiRw9u6dxiS02+c4Z8Nzumoh48W+z0GFy+q
             ClyhqdedA6k3WZIJi919e5b24mj5rqzcgrA6KMqnTJDKh2cuoKC1fI88w774
             co0XPDyg+v/RD2ET1fquDGHjeVyVBsknNZQ5lwvLeAy/uH+Ql5qECQ9WCIJP
             ydZZhB906hkHZ+vch1fG+vhgMtoXhtZ4UXzQwbJBL/4wxtOau3IgWGkJEImJ
             PK3KE+7phfn5YmGSjVCp8o1t2QxpwJ1ZPBuTrUWy15gruIP8e415f0UPUZjF
             G+p6JqsUzaBzgZvAg9nY/vHEC0sXuC7lnqmDxr8LU9JMD77XrBccXMP199d/
             10bJW8TH+yzqE4syjdUPEalQnwP/fh9us92eSdv50vr0/KPhzfWzcRwWFxof
             S15zlJe3xNj+BAURHCApKjBkh5emuLy+w9zn6vn6/QsbXWp6hZWcoLO6ytLf
             6/H+DhguNzs/VFVbg5SXo62wztPoAAAAAAAAAAAAAA0jNEY= )
]]></artwork>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <section anchor="ml-dsa">
        <name>ML-DSA</name>
        <t>The security considerations of <xref target="FIPS204"/> apply.</t>
        <t>In particular sections 3.4 and 3.6 of <xref target="FIPS204"/> discuss additional
considerations for implementing ML-DSA, including guidance on the
choice of hedged vs deterministic variants. These considerations
apply when ML-DSA is used for DNSSEC and especially during online signing.</t>
      </section>
      <section anchor="downgrades">
        <name>Downgrades</name>
        <t>Section 5.11 of <xref target="RFC6840"/> recommends validators to accept any single
valid path. Such lenient validators are vulnerable to a downgrade attack:
if a zone is signed by ML-DSA-44 and a quantum-vulnerable algorithm,
then a quantum attacker can strip the ML-DSA-44 signatures, and have the
lenient validator accept the forged quantum-vulnerable signature.</t>
        <t>This does not apply if the validator does not accept any quantum-vulnerable
algorithms or if the zone is only signed by ML-DSA-44.</t>
        <aside>
          <t><em>Note to editor</em>: remove this remark before publication. Remark: Ideally
we update RFC6840 in a different document to recommend validators to
insist on PQ RRSIGs if there there is a DS that indicated they should be available.</t>
        </aside>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document updates the IANA registry "Domain Name System Security
(DNSSEC) Algorithm Numbers".  The following entry is to be added to the
registry:</t>
      <table>
        <name>New DNSSEC Algorithm Number entry</name>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Value</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Number</td>
            <td align="left">TBD1</td>
          </tr>
          <tr>
            <td align="left">Description</td>
            <td align="left">ML-DSA-44</td>
          </tr>
          <tr>
            <td align="left">Mnemonic</td>
            <td align="left">MLDSA44</td>
          </tr>
          <tr>
            <td align="left">Zone Signing</td>
            <td align="left">Y</td>
          </tr>
          <tr>
            <td align="left">Trans. Sec.</td>
            <td align="left">*</td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Reference</td>
            <td align="left">(this document)</td>
          </tr>
        </tbody>
      </table>
      <t>* There has been no determination of standardization of the use of this
algorithm with Transaction Security.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC4033">
          <front>
            <title>DNS Security Introduction and Requirements</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>The Domain Name System Security Extensions (DNSSEC) add data origin authentication and data integrity to the Domain Name System. This document introduces these extensions and describes their capabilities and limitations. This document also discusses the services that the DNS security extensions do and do not provide. Last, this document describes the interrelationships between the documents that collectively describe DNSSEC. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4033"/>
          <seriesInfo name="DOI" value="10.17487/RFC4033"/>
        </reference>
        <reference anchor="RFC4034">
          <front>
            <title>Resource Records for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of resource records and protocol modifications that provide source authentication for the DNS. This document defines the public key (DNSKEY), delegation signer (DS), resource record digital signature (RRSIG), and authenticated denial of existence (NSEC) resource records. The purpose and format of each resource record is described in detail, and an example of each resource record is given.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4034"/>
          <seriesInfo name="DOI" value="10.17487/RFC4034"/>
        </reference>
        <reference anchor="RFC4035">
          <front>
            <title>Protocol Modifications for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of new resource records and protocol modifications that add data origin authentication and data integrity to the DNS. This document describes the DNSSEC protocol modifications. This document defines the concept of a signed zone, along with the requirements for serving and resolving by using DNSSEC. These techniques allow a security-aware resolver to authenticate both DNS resource records and authoritative DNS error indications.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4035"/>
          <seriesInfo name="DOI" value="10.17487/RFC4035"/>
        </reference>
        <reference anchor="FIPS204" target="https://doi.org/10.6028/NIST.FIPS.204">
          <front>
            <title>Module-Lattice-Based Digital Signature Standard</title>
            <author>
              <organization>National Institute of Standards and Technology (NIST)</organization>
            </author>
            <date year="2024" month="August"/>
          </front>
          <seriesInfo name="FIPS" value="PUB 204"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC6605">
          <front>
            <title>Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="W.C.A. Wijngaards" initials="W.C.A." surname="Wijngaards"/>
            <date month="April" year="2012"/>
            <abstract>
              <t>This document describes how to specify Elliptic Curve Digital Signature Algorithm (DSA) keys and signatures in DNS Security (DNSSEC). It lists curves of different sizes and uses the SHA-2 family of hashes for signatures. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6605"/>
          <seriesInfo name="DOI" value="10.17487/RFC6605"/>
        </reference>
        <reference anchor="RFC6840">
          <front>
            <title>Clarifications and Implementation Notes for DNS Security (DNSSEC)</title>
            <author fullname="S. Weiler" initials="S." role="editor" surname="Weiler"/>
            <author fullname="D. Blacka" initials="D." role="editor" surname="Blacka"/>
            <date month="February" year="2013"/>
            <abstract>
              <t>This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.</t>
              <t>This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6840"/>
          <seriesInfo name="DOI" value="10.17487/RFC6840"/>
        </reference>
      </references>
    </references>
    <?line 311?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>TODO</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA517256qSJrvvU/BrL7YVeXKFBBQ8jfV0yqoqCCKiDIzFxyC
g3KSg4jV1c8yz7KfbEeAZqaurOrpnRdrQUB8h398pyA+X15eWrmfB+AN+ybG
dhGAl4WR574FMM53/dwIMMV3IyMvUoANAjdO/dwLMSdOMU5SFH70rWWYZgrO
aP7ihVMGD88sIwdwTvWGZbndatmxFRkh5GWnhpO/lCDLQWoaRvRiR1kGrJcw
sDPjBSdbWWGGfpb5cZRXCZwg8JtxKypCE6RvLRtSfWtZcZSBKCuyNyxPC9CC
InRbRgoMKIoCrAJKWn1rlXF6dNO4SOAoF4eGH2ESFAFTKsg7xJYJSI0cssm+
tY6ggm/bby3s5aYAumq0QldJnOUvp8KI8iJE92NBVjASp9B1dgcpa51BVEDx
MOx/yRbDGhW/aVBUP3KxCZqHxuG0AI5DbOLkbz7Indc4ddEDI7U8+MDL8yR7
63TQe2jIP4PX+2sdNNAx07jMQKem0EEz4ZJ6hQnnmjfwO3+6FGhKANHO8k/s
7lNfG2KvfvznRP786auXh8G3Vssoci9OEfiQJ4b5EVzX4Sv/imnv8+oHThEE
jRENjez5IVTciPxrDe0bNgriwnYgNKB+CBo8TSP7m/X+5NWKwzvPD9LflDjx
fLhclhf6oMb8mfgkjt3ggXCWNW//za0f1ZRbUZyGcMa5toj1eETh3e7HJfVx
SaNLZFLQot5qsl/75QtUG9hfeKeSG5FtpHYj7Duc9d8LEh6Skmrh4TQhyiD5
IgdY7LzPzDD4P7YBlhfFQexW2E+SoGx+bgjWTgfNnaRe8H49koHUB5kfOfGd
DRL/DZPVYeMWSAcjdQE0nrvt2LFfWyeBvzI42e8gBq9o2iua0ULEHvFiGJy+
X/Yp/K3Ven19bbVeXl4ww8zy1LDyVmvj+RkGg0sRgijHbJBZqW+CDPPiEstj
LEuA5TsV9mdAtr4Kcz81zv8zBkNDA86Hn0MLRVECu4ea1k9NzPj5FcOEHCsy
+ErugVv8eKEoLDFSaFzQXCFySErHjyB/SOYeSF5bHy9DhUwQ+OAMX4EqmABO
spB0cCTCDBdGlCzHDPsM0sxA64AIwQgF2aKo2YLLamBWWiV57KYGNGbLCIIK
S0EAzjCCYbc4hkEjTaAZpDdMQ9+2oVW3/gItJE8hXhYymFar0e07VkJCXi1c
Ghs2JPhJjd9+u9n3779/f7+h0A1ErnUfoNFAjc6DdB8Q2zfL/gQ1BCBJ47Nv
gzpMwEWG6iDBkPWiRYDGaUDcR0WawodQLIR8COM1hCQpoJ9/UGsZ9+WtIYOS
wHAKsDXMXIg7moiM8qUxGh+qBoLATyBHDOJ/Bq13Stg7JYwfocxXq4gM9vff
IZyDIEAzbgJ9kPvEH65GVedLyNVPmxWGpoRBxZAcHvTJCK4n0hLeQ++A2RSa
jwONHpJoIhFCxgxgTmnIYD89ivszxBO6AzS7FnRpoxH3NgUiNvhXbASuPrQ9
s/CDHObVIrCRWRqQUu1kcXAGmBnn3k1cCOyNT4YBx/Etv0aisYZmOnwrBVB/
8JkQvHfBLQF/NgKoBAxBNlZCFSANiJLTath8IAph/+23WxD9/fd30G+e+L+K
o60f3R+K/CEIBqM8gJm89OIMfCwZcomaYLN2rc9rF9wqqnc4Yui10DyROPeH
GVyMWwH1yfVb/x+ujzgarX/F9THsM2iNRyPIUgBaD0ELpuT3CPX9fsnQ9ZLe
b/u91x8D8p0iqP2tcVq4vP8nwzjlO7qZ8/uGynqtCBMoaxYXqQVaKbBilJh+
Wq+zn5ul/5Og+o4hetKknqz25tb7Ot0rUoy8BzMA8cibIEMwOGb6eb1oHzMC
A+IKMWwh+T4Xge/vvH5i6xmNolkIUYfVyVe5o9V4SAPxfdkfkb5LFxpHtMD5
R0TLCmiw0I5aKHAgOP0mWkAUX1HgHsXRGUVIWFzWbDmEvl/fo4UBSCCsrFH9
JqrK5tv35n9MWtbXa36lCmueQ9fKdLBYvF+0bm8o06W64D6uPmaOlqLIS1wz
GY5iD0Otb+Jg/61Z529LeSMspcHiWyP/Z3tB8bgxfBTx0gRFLxg3s9Y9s9fp
ZjiS/+//EBS03X+DYZckCBYab3PTJ3rIklG4arjFEXSA5hZCVbWMJAEwKUAq
BorSRoJiAMQcrl0Gi4YIQ4EJovnLfyJk/vsN+3fTSgjqr7cBpPDD4B2zh8Ea
sx9HfpjcgPjF0Bds3tF8GH9C+lHewf7h/o77p8F//48A+if2QvT/468tZEKN
Q2LrmxfCi9oLYU6LPrteYQZN4sbQXszPGscxMKJLkC+xlcMq52wEBUCwJnUx
AVfOrFDUrme5ILptgz6l0ob+6xxUExjtPpUXsNCqX6VfCRT6P4WspuKCFgQi
K7brt6H5IC5yIyIkhsE0ADNOLV+jXuseZLAmyCApUZwPExiVYRSAW9YUbsdQ
sYJ2ZYicWcGCuWaCRm5Z+RMMD/Z5l7f3SqJXP8uLMG4C3T+B+CPrPCJMUiT+
JwjXcqG5SMwfoEWp7mtgfxAUAdv6CtiPavkD1+gpeH/GtfUv4/pJ98+wtv4U
VuWjXEBB5GZgKHjAIADzZVOBfTD+lsB3v90j8BlmUxjYWz/5r+D1OxbFTdSF
8ecFRnXv/hybwpv7zuBWjcA9YJLXfpCDy13F1k9WfkFCXkEaYwGI3Nz7uQ4y
XxlKVi8AEpR+7f5o4ShyhzDDG24DDZrbZBpU/N73CM2Dzxxan1a4+0q89mv3
+Vyf1+b4UfVI9VeW5jPOl8n5R5tFsn2YWfOZBgqRxZb/UbJ9yv6ftjnRZyat
HysA7F4BQGU3Q46okfBR6ez6aPtX6wXv0d79fTfSuqVEYSANUD7M4M7h9r0F
5Wx0USvNXwxklTcNnDgI4hKZBmjGv99Ta5ZXQbNTvgHJvEPYlPvf67SB8u2n
LdwdOVRQQB2gRkkc1RbOKTe1GljfPaeuC+GduGvBeqeuZ94TNlzTD3O2UZ0Q
wrSe5bfqzknjsJa1ew+9GYBANNnspoac+mc4/T0afn/f8Xz4Wvk5krw7SuuB
4bsjvC8l9lOKChzIFdohSqnI4gGs2DIULozaj1o3VOv6Fjr8C7Swl9rzU9Bw
9GFVA1UeAsu4GUoj2/XRaFpfVFTfmzgCK3CGerlHqzo0NpGgTFHKt9H+4M1A
5vB766/YL5qRohD5yxu2QZXaGaB9VdbsNbP6QwlEFolC9O/btB/s/BXT/CCA
1KD7FYn9aO83V6jtEBKLUfWJNin/+Mc/WrfVeIHavDRfPd6wM/Ha/diAvCG+
cBMC1aaon1sfy/eGDQb8aFCuxkPXEkareMEN8CV3Gax5T1TH6/1uMjwak0tp
T73+r6078uiL1CvWZXAcE6R7kifpHtatGd0+4tz+iN4ctwLlREn5mKZFSUkO
SrUjZZ521mBGnuPd4JhdzOScBXKlr/PVeWICwx4ue6fDIyU5Gs8qfJGr622y
zIbDdlbs/ZwhOi5lewd+r+gaccyWO9wPlgtvQ49OK7U4uKGvp/wTJfwqposy
ZAy3Krb8nrByTl70aN3NBjxFCePOHth+5duidCK2m1Q4pcOxT8+zYbp4pBSD
pbg5k7K70E3xistWsbU70XQZDZleKETRReMnpUxcXS4+9WTm3M3BSV4slmSw
WT9SmrMHSToBsb3T1CUOUjxghFG2VujdqsDBYX0apYxXaKsLcRhqxUbxBqRy
nk+C0YodPFJSNG3XmTt7qFln4p0NM1Hnp+QA1pE6JeYbIpGH+tHT9wtuW7F+
z/BXWirtxxHHx6NHSnY3vlJiUgUOKW865jqeLyODIwLW2XU7E84YHJiROW4r
Y74cseyE4afa3t7KpyPp9J+sgCT1UbedRNLa6Jg+Z6ryUXPUveMM92vamsVD
JnSJI9GOhpORzkmyNWFWwyJRmMx+pNQ9TjKdya4Tu8riyVAgxE3Rj3reMil3
+Hgpr8p+DlmNVlvd7Ub+1NmT8/N0pix3hyecVsUq3uGi7k0uPB/ORgHp8eWK
3hqMsM0NS6d1XDSqk4bTnj68dKwy60bqMen1DFp9pMSMs8sh3i4P7XnVb3eZ
ajdZz0fWPGWnwZAvmQ2bslFHdI5Tb3GI6XHgreecwe719XTzSInU92l0Coy+
DnDaubj9dJqPbYrR2qzjm91ppPPjqZ7F48KWE1W99NjSOkcbVRG2nUdKa/Is
abJgjUi1t+waR2pqhFs9LmcXb7sT9x1b0IwTUyi7UqD21knEZcCQlXdhI2L7
SEkMCVxdSwYxZucTxlhP5KKq5uKyN1sqvWt7Z03MWWrvprx4OYKLquKeo2ui
NXQ4ZvVIqaNwg01oL468Vxy7o8PEHdjieX0NaHo2jBTgHO1OvLDHI9kP+gfA
8anbn5k4dZiPyidKHXvqM+wov+hRz0hnDm9c5tqqrU1oc7iNRWEdTAhZKnTi
nGsTjhmO4stOd8PxkTg9UjoeHE4L2h1lq6wSk5D6R5/e8afCphRyqFkX/XQZ
rU0Nz4S5GyXigfb7LhC1rk5JT1HFBJ2ddMIZqVyoYenv17PBfL8Xr0Hvwk9M
UQIJcDPKGR7Xa/wirUy1LZ6CbrowSyZ6pLQzdTOjaZ0up5GxdQB7XsCgF3GT
yFLmhMBTvd1o4oxj/7LJR/0RNTDlkBl1pVU7erJxxlnt1iK5H5u4WQmC5Pf4
Q59vZ7g5IT2bMOaXQio6cn686mV/pnnuYnM55qMFvzgwj5QKtiPOq/X6cFgU
8XznVqvN3OPBYMT1e5y0WBUL46z3SkKjFXUQdKfZHMinAcUszE76SEndzAXV
3k9d/ZAoG32dRl67HKnO0S8OXMKuu+Q8JCrAX69dZbg5Xuy8fZjNVeWsK7tH
SqODaUtzVT1NwLq/zMj+cG2OjPwI08h8cFlWocYbc+8i+Ot9BCNTHF/Gg/0i
4Ve4lz9SYteqH1uMkJXhuPRMii7w3cHeRlmpuISY9k7C3HfxxQUkJ98oNCk/
DGBNXRIHltWerIBj7f1pFW+j84yJr8luHsuSai9GnZMs0nEwSjfOtRpx57h3
Pg+HW2rf8dQuB11qP36kpOdupz/JvMmpx8vzubkVryuOcrfxUQf9xToYW5f2
yhGVTRmdO93lBmq+h6WhqhmDpyx1DeBCbA4znWIrpqSXtEOe6JB0vJ3cDzqX
UT7THKXjk9Odx8mxUYoEURz1KU8uWOGRErgex+XqIBOn8piJTLe7cGTV8SQu
N6bFlikyS72Wk74UlAJ7PFnCbC/1NDPJcnYTPFIyytO0dJeTeXG4js1En4FD
3mN0WkpifxDpnuqMT0HQdlxwjUxxWOZbL6GlYueJ/SecKm50nY0qjnd//RX7
+Y+qFAWj2T7JogqFfK5R+gRpmYRBkoaDU90+DkinR9osYeGMRVAAPmKJvuV0
cbzbM/oGazE9iu0BlmQo85ESZTrGH8og7jACr09jXz8//4O3m1IezUES16PP
pRVF4ThJoCcEFJvEeyS8bNR8YPAw62hXyvRaDnuSkx9WymDcy6IRmBtFV4pP
yUJyCcbrgKm+7S+6euJ38eC4rnyFGi9E8clAT5vD1XSIQcdUPJc66ck+iJzT
TuoXp7E2Zic8P1u6OSBGY3tMTUY47fJDtd+fp5XzSCmaDCzoKYZTsl7OXfT0
FJ62iia1CbfQetNKVccxIRTaJtLnhacnOTc7ntpi0Kb16ZMxUEmb3NjlsS9O
e/ks2OyPHXVriEQp7OQhuXdn7faRw69eldFWt59ec8tYhuIuZ8BTuVkN+H23
x1mE3pln6Xqla+f2Tu+MNoFfeG17MpvGk2IT0vNSwYus36eKoyaNOqWgdpSn
MiqYxENuu8s2BNPdpEywcfrJjLr4F2suSP0omyvji8we2gPTkGgldoTBOaEW
E2G8cJ9S8TxbbzvWCezjvgzcLUfy3mBFdqbbzbJbLPvn4LSY9yJtu52TbdLY
z4UFyZ+uB2+9nz8FYZrzxFJhddec4HA7dp3skrNuSdayGgx3VWZvC4M7RGph
hPvtYLRU022vzyykMO8/hQSNi3ZaLMsin8pH+ixV0xPT1qduj1WBnijXCz4A
HcIQHJ/U+NxglymdTYR8GDHnJ0fWfPY4WxdeAfP3zmFHi+G2s5guOrIAouFl
p0QpuSxdmhoUikTm4ZEMuKo/dObX6/nySGmzhCnqQgE7ZpndmVlpAwXmA3YW
VvzZi8YwrwjMdNJ1IrJ97KfubCFMkyylEt0TvSeH7igrzYgPl5wmIl4Y+4QZ
wEI+G4QjW5T7xEKRLrBAFI5zSwbLbheW5VuFW/Ym1+VTeZBFw+XV9NQd65rj
tGtI246WmlnH0sXBghBwYT4h8cMx5B2dlcFcwr3d6DKdxZQnP+G0IMOQtfxJ
UuyUXiz1nd6+MANpU673fZNKAsXaCqOkGm5olVvC+LlmO20uOgYL3Lk+UhKW
a3GzjhKO8E7U8KSLriSWZ+s6drtcqixWcsca+vNF1M3jWXpUCpU1drHNn7Ru
8ITTGhZynHra5FNXnBsZfQZBCHcevDQw/Ys/7Ef0NealSFxsmbJDdI12tdxs
SE0988qTjU9PY5YcOyvRXgVdJoorUIYHdazHiZ+OJltmcASmvc02e7LH5fvj
RDPCxc4KuyVpP5Usgz20nyw7V/POLIjKDt+DNZl2XLb78nk6IPOzs1LSviON
qCDozKd2mfZtfNXPEtlaPskkioVP4jtuD5JUDhOG8pScEoaFvyoyO+wqq0w7
rM6Gmrn9rDrqNkkpnVJa+ZPsqXDdGfGEibX9fqQXiXOeWHjmmm32dNFV2lEG
+3l5oReHvXFIi/OKdgJgDvIUlg+FbE6eYoFJCj29b1HCmQvNARMcTuKcwUti
J7RLtXdQNIi44QtgoK4JY8OS9Hws8l44nnSPT96S0ros0L1S7CW8wB6GIt/H
g6LHdR3q2m77ljJVZvReMjptuP0BirBhqZDaHHoReErqoYRr0XzsXif6PCp8
bjIDJT0eR84QPznnkyqpck6kW0NIe+l1OFxQh762mp6WMdF7KlzbeBIJp/kG
EHpfvIwjGe6igTY1uptObwZ4WeHo2XiZ8NolI8i8vGxGFDlMNyPrqISPlFIn
PGbOJZwZeOg4gbGUp8eD4W2SNBXy2XVCAGe6HxV0JNNpZgX6GPe45ZpY6qn7
FDNJwYsmxDbOBXlItTvtHt4uOPxknfbdBVnF0WUcrJR+xoeitfPZy2pzsccT
SloeO5unjdCExpdBReTrhFXjxaHccHkgHLwesbiygXEwB4a5pbRcONs9qzTW
/BI/jgf5VXCd2dNng61oZNpZjRnAdk+r4ca7no8jKetHbmbgh91sQUxTfi23
T0dfXYw4MSXY8dYPtVC4PhWJo+OaTVxW06Dp7elj6tpbU5DU0yGrqknqy7xX
kbMISJq9tMfxoDxq+cQUkpU3zcinEngxTSbsRZbHbR4mpPAgGT1m6O3OlGUU
6XQf9eZ4SEni1uWqcrKLPXw5AR053q2o51iQ93hz6pqj1ZLd9tsdoi1qJaun
KmPmy8mMnG13oFrv9tXMSKO2FckLItKWwalnitzTZ4PQuC43ki5btMpLyplb
0IQX2l2N6xE+WbBmfhKuhyhULq4rT9fZ1loak91U7Brq7KlWSbm89Al+39tM
g5mRK20hP2grccR5fbdDLcasQqraZGyRhOiHWamdXY84DDuUt3/KnOyoLyuj
ZAC2JGPv4oEU5etOsAgziqT6fXs7I8pKmhwMSdoRfu6fxvtMUqPuotp0nz4b
2FvVHZZH57okBEqNPE4ws+lMM7MeF3Rokvcp0Uzk2S5aEK4oWYzCEfxxQ4zA
nn2qxEA2HZM4jIS52du2T/KS3Ix4ksmqIRvoFLFUlnv3JO/nneW0ihfAXoWb
5TjI8JV4eLKCMW4es24yCzsbjhP5QrW9IpCNPNKHkrADl5MkhCt1XPmJNWM1
eh5xjJbS7UOlLqonGx+u1okmX/3EkceDkUnbdKDJeXr2qGOR7vNupthq1dZm
82JvEinc6W/02UnGV5z7tLHe8vsFHc2iy0lZc6xz6U3F9XS35I5bPx6OQ0V1
S5neDYND1NkngjvpCxeK9Kq5OMr9p+rwTLjCvtsJ4b5gWh1ogblY3FTd6NNK
ZNtzRQdQWqZUo8iN9WJ/lVkJ1tfXuL8Q2o+Uyq4YM1lne/DCbLBY7q0ig3V8
hourPZ2k3tHS9+rZPbP7BbtuE+OwN79UXeuQRJPTE05aeZGYfSiVHYcZtUmC
C8Cl18bZmKxcHxcJidd1fOzZxjC8bC+5cjCHYbeYF2xuPG1i8euS7lLTXeA7
4+PFYSaeGV/MiY325cetcOAW0ajtx/aqWpSCj5/PFtWld0dqsh5mT1srjpYv
Tve86eauXNEZtzNn3WBD90VwnNubzjQ2C5db2gUe5BMQjQ8wfXj2rLDPq6cP
WuPx4TQ7EjB8HC4XW+6u9vNAmS7P5IDL1ydXwLfTxSzkR0vf2acsXmhhQBRX
Q73O8afPBpsiCPtOxAROMu7y2myvZCfC3620wl+XbMHYF1/BybZF6X3pWoSx
R/W19hWfjKv208ejUVB5JxvYA+bY1XRh5rMEC2iTpMIDnZ6ulpsOmLl4ijYz
bu6RVhHPR4Qj9Ptlr0c9UrJifCdzlds+d9awqt8QzqngJtMD2FbbYXaMJH1F
B+V5AQZVp5i2VwF94kcrVhsJM/nJMm1d94YsznjHqd4+Wx7hTNpnzxXzeOfl
OqXurqvSnA0XHaq85Eu47xNcbXKc8UL4FOnkeXfOt3uJ50T0Ppwoh+0o6cdE
Tq4uSTkjdHlYbFJVqwjaTQtB7gOKoB1clVX98FSxTtoJMztl6tUYXl39PHDZ
aN85T/kRnu2KUS+ITiF3SfsLlZ2JXK+3S4eWtRNlgmXtJysgcHOm9TfTdnU9
8VRWHWxV5o1gFZVyx/HYImNJoNhnGj+neGcue1dHu1rrUhtf4qdIpxD0NZiB
7kU6tIewRpqOBsn8MDx6NAiLRdUu2SvcokRMZ5WZOy1hPF2z4sWSqfLFEyWm
M21znltIV+jG463p0souZsjymsvx4OEPP0j8Hn2kQAc3rb+8N30+HS7CR3+5
N4yjg7uPHqLHM8jHc2vMSJKgem21hAg1AeW+1XQs3o+Fu69UfdrVfWWeZ6Le
viLLMMO2/aazt/XECh1b1UfvqLMGneY14qGjTSso6tNIt/BtI7LAvXXN8mLU
rQZZecB20Tlahn15/pe9ouPJDDyp16r1aZoFP1raCtQc9/HbgFojUDfo1ads
dpHWZ/9R3Ypy6114rQHl4jJyU8NG57SfmkA+jrFRYzAEAx2phlBNO0Mnf1Cn
+jAPHUhaFkjyumcQHWgGoFU/h2Dn3iumFJaHDudRe+LniejY8FwE6Mj11plo
YPZdFMzIc8M6vrV81I5xjaP6WPN2/G5Wn0646wPee8/dyyeC7weJ31FDTPTx
0o02SDHLiOpWguSp6e3zuSei7xlnUC/dD2rcdc/r8+0UreYXorzT+2jdA1nd
/9Aspd+cxH5Q/Xj+Ae2PdD+32iIzbKjcwap7sr5A7OmMVorzGnwALTxOf3mD
yxzGtbp1F0BopEfMbJpIm06c2ghfsXX96A0TbIAMDJIq7we092byuv8L+pDj
gLTuU7w3oEF278b0aEuQjF834iBnkVfNx77sploKbv/6qJOIU5qjbz+ykVCg
PmmvUKPAvXP2jH63gc68637rH3sVnvsoG+mzj9aGWxNE9eVvTH5oTP+hxyP7
dmsw+NT5ECFyfnbrJ4Fxpek/R8Z15/bWav0dG9dtP3/493dsW/clfRpp/f3l
n/z9+AKcdO9H+WNOqC3kYQRO4ur2l6SOFV9O+nCmj0liBE0rgvHtjzjdjuIf
OOnInJVbr9VXk/bPI3DSJjUiGD3hEr1+zem/fvlxkpqBzwH0mScUb7D/Z5O2
jTG/w/L1JOGeML7m9y9M+uD39aQ1qH3PAtiXf3/HfnpoDf0ZTvrtrfllzK/f
JFDe+fzQvlQb8rffWy2I5KZ2StSYawIYaKP4PZ29/4ggu/0E5t5Uf+s9eW9D
8bOPYNa0d9RLaDTZ6O5qtx9RmDB61z1V1jGKywAmUSR7BiVv+kGA/es3xwgy
gOTbLLll6/8BMMk1AYc3AAA=

-->

</rfc>
